Sign inStart for free

Legal

Data Protection Policy (“Policy”)

Last Updated on 1 July 2026. WORKPLACED Technologies Ltd. and Workplaced Technologies Europe BV (“WORKPLACED”)

1. Purpose of the Policy

The purpose of the Policy is to:

  • i. Comply with the law.
  • ii. Follow good practice.
  • iii. Protect customers, staff and other individuals.
  • iv. Protect the Company.

2. All personal data (as such term is defined in the General Data Protection Regulation ("GDPR") collected, retained and processed by WORKPLACED will only be collected, retained, transferred and processed in accordance with the GDPR and WORKPLACED's Policy. Therefore, this Policy applies to every server, database and IT system that handles such data, including any device regularly used for email, web access or other work-related tasks. Every user interacting with company IT services is also subject to this policy. Information that is classified as public is not subject to this Policy. Other data can be excluded from the Policy by WORKPLACED management based on specific business needs, such as that protecting the data is too costly or complex.

3. The IT department at WORKPLACED (“IT Department”) is responsible for:

  • i. Briefing the WORKPLACED Board of Directors on Data Protection responsibilities.
  • ii. Reviewing Data Protection and related policies.
  • iii. Advising other staff on tricky Data Protection issues.
  • iv. Ensuring that Data Protection induction and training takes place.
  • v. Handling subject access requests.
  • vi. Approving unusual or controversial disclosures of personal data.
  • vii. Approving contracts with Data Processors.

4. All staff and volunteers should be required to read, understand and accept any policies and procedures that relate to the personal data they may handle in the course of their work. (From now on, where „employees‟ is used, this includes both paid employees and volunteers.)

5. The IT Department shall ensure that there are data security controls that include, as a minimum, but not limited to, logical separation of data, restricted (e.g. role-based) access and monitoring, and use of commercially available and industry-standard personal data encryption technologies.

6. All emails containing personal data must be encrypted.

7. WORKPLACED shall provide all employees and contracted third parties access to the information they need to carry out their responsibilities as effectively and efficiently as possible. Therefore:

  • a. Each user shall be identified by a unique user ID so that individuals can be held accountable for their actions.
  • b. The use of shared identities is permitted only where they are suitable, such as training accounts or service accounts.
  • c. Each user shall read this data security policy and sign a statement that they understand the conditions of access.
  • d. Records of user access may be used to provide evidence for security incident investigations.
  • e. Access shall be granted based on the principle of least privilege, which means that each user, application and service will be granted the fewest privileges necessary to complete their tasks.

8. Network Access

  • a. All employees and contractors shall be given network access in accordance with business access control procedures and the least-privilege principle.
  • b. All staff and contractors with remote access to WORKPLACED networks shall be authenticated using the VPN authentication mechanism only.
  • c. Segregation of networks shall be implemented as recommended by WORKPLACED's network security research. Network administrators shall group information services, users and information systems as appropriate to achieve the required segregation.
  • d. Network routing controls shall be implemented to support the access control policy.

9. User Responsibilities

  • a. All users must lock their screens whenever they leave their desks to reduce the risk of unauthorized access.
  • b. All users must keep their workplace clear of any sensitive or confidential information when they leave.
  • c. All users must keep their passwords confidential and not share them.

10. Application and Information Access

  • a. All WORKPLACED staff and contractors shall be granted access to the data and applications required for their job responsibilities.
  • b. All WORKPLACED staff and contractors shall access sensitive data and systems only if there is a business need to do so and they have approval from higher management.
  • c. Sensitive systems shall be physically or logically isolated to restrict access to authorized personnel only.

11. Access to Confidential or Restricted Information

  • a. Access to data classified as ‘Confidential’ or ‘Restricted’ shall be limited to authorized persons whose job responsibilities require it, as determined by the Policy or WORKPLACED higher management.
  • b. The responsibility to implement access restrictions lies with the IT department.

12. Personal data may not be transferred to a device that personally belongs to an employee and personal data may only be transferred to devices that belong to agents, contractors or other parties working on behalf of WORKPLACED if the party concerned has agreed to fully comply with the letter and spirit of this Policy and of the AVG (which may include demonstrating to WORKPLACED that all appropriate technical and organizational measures have been taken).

13. The IT Department will provide operational procedures and controls to ensure the safe removal of any part of the IT systems or any medium to make any information or data in the IT systems unreadable or unrecoverable before they are permanently removed or released from WORKPLACED's possession.

14. Where personal data is to be deleted or otherwise removed for any reason (including where copies have been made and are no longer needed), it must be securely deleted. Hard copies should be shredded and electronic copies should be deleted 'hard'.

15. The IT Department will ensure that it has appropriate technical and organizational measures in place to protect against unauthorized or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data. Appropriate to the damage that could result from the unauthorized or unlawful processing or the accidental loss, destruction or damage of the data to be protected and the nature of the data to be protected, given the state of technological development and the cost of implementing measures (these measures may include pseudonymization and encoding of personal data where appropriate, ensuring the confidentiality, integrity, availability and resilience of the systems and services, ensuring the availability of and access to personal data, restoring the availability of and access to such data in a timely manner following an incident, and regularly reviewing and evaluating the effectiveness of the technical and organizational measures taken by the Commission).

16. All electronic copies of personal data must be securely stored using passwords and data encryption.

17. Only Users who need access to and use of personal data in order to perform their assigned tasks correctly, have access to the personal data held by WORKPLACED.

18. All Users who process personal data for and on behalf of WORKPLACED are subject to, and must comply with, the provisions of the Data Protection Policy of WORKPLACED.

Turn workplace data into decisions leaders can trust.